File name:

Links Grabber By Mf4Tn.exe

Full analysis: https://app.any.run/tasks/f5188a55-d77c-43e4-a083-ef1375a42222
Verdict: Malicious activity
Analysis date: October 06, 2023, 00:15:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
UxCryptor
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

52B8A584FA6DF999FEAC0A2DF6C4DF9E

SHA1:

ECB7F2C26AB2ADE4CFBC8BE927C431986CB972BC

SHA256:

F8BCED63E388F43D1A3F0FF624DC71A0DBBDAE02257B6AB0BA30BAE442D0C33C

SSDEEP:

3072:HTPt0CPZeMPufSVAqoEKOfGYVFnp9rbIy0E:HTPCCwLfSuqo8fpn88

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Links Grabber By Mf4Tn.exe (PID: 2988)
      • Links Grabber By Mf4Tn.exe (PID: 2484)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • Links Grabber By Mf4Tn.exe (PID: 2484)
      • Links Grabber By Mf4Tn.exe (PID: 2988)
    • Reads the computer name

      • Links Grabber By Mf4Tn.exe (PID: 2988)
      • Links Grabber By Mf4Tn.exe (PID: 2484)
    • Manual execution by a user

      • Links Grabber By Mf4Tn.exe (PID: 2988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:12:31 01:36:53+01:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 119296
InitializedDataSize: 2560
UninitializedDataSize: -
EntryPoint: 0x1f14e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Links Grabber From Notifiers By Mf4Tn [zone-h]
FileVersion: 1.0.0.0
InternalName: Links Grabber From Notifiers By Mf4Tn [zone-h].exe
LegalCopyright: Copyright © 2021
LegalTrademarks: -
OriginalFileName: Links Grabber From Notifiers By Mf4Tn [zone-h].exe
ProductName: Links Grabber From Notifiers By Mf4Tn [zone-h]
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start links grabber by mf4tn.exe no specs links grabber by mf4tn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2484"C:\Users\admin\AppData\Local\Temp\Links Grabber By Mf4Tn.exe" C:\Users\admin\AppData\Local\Temp\Links Grabber By Mf4Tn.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Links Grabber From Notifiers By Mf4Tn [zone-h]
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2988"C:\Users\admin\Desktop\Links Grabber By Mf4Tn.exe" C:\Users\admin\Desktop\Links Grabber By Mf4Tn.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Links Grabber From Notifiers By Mf4Tn [zone-h]
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\links grabber by mf4tn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
66
Read events
66
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info